{{- if or (hasKey .Values.certManager "route53AccessKeyID") (hasKey .Values.certManager "route53SecretAccessKey") }}
---
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
  name: route53
  namespace: d8-cert-manager
  {{- include "helm_lib_module_labels" (list . (dict "app" "cert-manager")) | nindent 2 }}
spec:
  acme:
    server: https://acme-v02.api.letsencrypt.org/directory
  {{- if .Values.certManager.internal.email }}
    email: "{{ .Values.certManager.internal.email }}"
  {{- end }}
    privateKeySecretRef:
      name: route53-tls-key
    solvers:
    - dns01:
        route53:
          region: us-east-1
          accessKeyID: {{ .Values.certManager.route53AccessKeyID }}
          secretAccessKeySecretRef:
            name: route53
            key: secret-access-key
{{- end }}
